Software Firewalls versus Wormhole Tunnels

If your host is running in promiscuous mode so you can view traffic, but there is also a firewall on the same machine, a necessary question to ask is: "Which application does the traffic see first?"

If the captured packets see the firewall first, they might be filtered and not seen by your sniffer. On the other hand, if the sniffer sees them at all, they may have bypassed the firewall altogether.

This article discusses some scenarious that involve a configuration which includes personal firewalls and promiscuous mode drivers running on the same system.

Software Firewalls versus Wormhole Tunnels






<< Home

This page is powered by Blogger. Isn't yours?